Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Magento RCE Flaw Added to CISA Vulnerability List

Critical Magento RCE Flaw Added to CISA Vulnerability List

Posted on June 4, 2026 By CWS

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include a significant security flaw impacting Mirasvit Cache Warmer, a widely-used extension for Magento’s full-page caching. This decision follows reports of the flaw’s active exploitation in various online environments.

Understanding the Magento RCE Vulnerability

Identified as CVE-2026-45247 with a critical CVSS score of 9.8, this vulnerability arises from the deserialization of untrusted data, which can be manipulated to execute arbitrary PHP code on vulnerable servers. According to CISA, unauthenticated attackers can leverage this flaw by inserting a specially crafted serialized PHP object into the CacheWarmer cookie.

This vulnerability affects all versions of the Mirasvit extension prior to 1.11.12. A patch addressing the issue was released on May 25, 2026, highlighting the urgency for users to update their systems.

Exploitation Details and Security Implications

The inclusion of CVE-2026-45247 in the KEV catalog was prompted by Sansec’s announcement that any storefront request with a crafted CacheWarmer cookie could exploit this vulnerability. The process involves PHP’s unserialize() function, which is executed without requiring authentication or administrative privileges.

Sansec further highlighted the potential for PHP object injection, which, when combined with existing Magento and dependency classes, can escalate to remote code execution. This discovery underscores the need for heightened vigilance among Magento users.

Current Exploitation Activities and Recommendations

Imperva, a security company owned by Thales, has reported observing malicious activities targeting CVE-2026-45247. The attacks involve serialized PHP object payloads delivered through harmful HTTP requests. These payloads are crafted to trigger object deserialization, ultimately allowing remote execution of arbitrary commands on affected servers.

The primary targets of these attacks are gaming and business websites, with countries like the United States, United Kingdom, France, and Australia being the most affected. Although the perpetrators remain unidentified, the goal appears to be identifying vulnerable Magento systems and verifying the possibility of remote code execution.

Federal Civilian Executive Branch (FCEB) agencies have been instructed to apply the necessary patches by June 6, 2026, to mitigate exploitation risks. Website administrators are advised to scrutinize storefront requests for CacheWarmer cookies with values starting with “CacheWarmer:” followed by a Base64-encoded string, as these may signal exploitation attempts.

In summary, the addition of this Magento vulnerability to CISA’s KEV catalog emphasizes the critical need for patching and vigilant monitoring to protect against potential threats.

The Hacker News Tags:CacheWarmer, CISA, CVE-2026-45247, Cybersecurity, Deserialization, Exploitation, Imperva, Magento, Mirasvit, PHP, RCE, Sansec, Vulnerability, web security

Post navigation

Previous Post: Malicious Code Stealer Deployed via Google Sites
Next Post: Critical VS Code Flaw Enables GitHub Token Theft

Related Posts

Google Fined 9 Million by French Regulator for Cookie Consent Violations Google Fined $379 Million by French Regulator for Cookie Consent Violations The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More The Hacker News
Botnet Uses Polygon Blockchain for Resilient Command Control Botnet Uses Polygon Blockchain for Resilient Command Control The Hacker News
How One Bad Password Ended a 158-Year-Old Business How One Bad Password Ended a 158-Year-Old Business The Hacker News
Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown Malicious PyPI Package soopsocks Infects 2,653 Systems Before Takedown The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw
  • Critical VS Code Flaw Enables GitHub Token Theft
  • Critical Magento RCE Flaw Added to CISA Vulnerability List
  • Malicious Code Stealer Deployed via Google Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark